This Privacy Policy explains how MEDSUITE (“KioskoGo”, “we”, “us”) collects, uses, and shares personal information when you use the KioskoGo websites, mobile apps, and self-service kiosks, and the KioskoGo Merchant dashboard (together, the “Services”).
KioskoGo provides ordering technology to businesses (“Merchants”). When you place an order with a Merchant through KioskoGo, that Merchant is a controller of your information for fulfilling your order, and KioskoGo processes information both to operate the platform and on the Merchant’s behalf.
1. Information we collect
Information you provide
- Account details — your name, email address, and phone number when you sign in (we use passwordless email one-time codes).
- Orders — items ordered, order notes, pickup/delivery choice, and history.
- Delivery details — delivery address and, where you allow it, your device location to estimate delivery distance and fees.
- Reservations — party size, date/time, and contact details when you book a table.
- Payment details — processed by our payment providers (see below). We do not store full card numbers; for saved cards we retain only a secure token and limited details such as the card brand and last four digits.
- Communications — messages you send us or a Merchant, and support requests.
Information collected automatically
- Device & log data — IP address, device type, browser/OS, and app version; we record device and IP details when you sign in to help secure your account.
- Usage & analytics — pages/screens viewed and actions taken, collected with privacy-focused analytics to improve the Services.
- Cookies & local storage — used to keep you signed in and remember preferences. See “Cookies” below.
- Push tokens — if you enable notifications, a push token from Apple (APNs) or Google (FCM), or a web-push subscription.
2. Permissions our apps request
- Location — only with your permission, to set delivery addresses and estimate delivery distance/fees. You can decline or revoke this in your device settings; some delivery features may then be unavailable.
- Notifications — only with your permission, to send order status updates.
3. How we use information
- Provide the Services and process and fulfill your orders and reservations.
- Take payment and prevent fraud and abuse.
- Send order updates and service messages, and — with your consent — marketing.
- Secure and troubleshoot the Services and maintain records.
- Understand usage and improve features, including AI-powered insights for Merchants.
- Comply with legal obligations.
4. Legal bases (EEA/UK)
Where the GDPR/UK GDPR applies, we rely on: performance of a contract (to provide ordering and fulfillment), consent (e.g. marketing, precise location, notifications), legitimate interests (securing and improving the Services), and legal obligation (e.g. tax and accounting).
5. How we share information
We share personal information with:
- The Merchant you order from, to prepare and fulfill your order.
- Payment processors — [Stripe] and/or [Razorpay] — to process payments.
- Infrastructure & hosting — our cloud hosting and content-delivery providers.
- Email & messaging providers — to send one-time codes and notifications.
- Analytics providers — to measure and improve the Services.
- Push providers — Apple and Google, to deliver notifications.
- Authorities or others where required by law, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising.
6. Data retention
We keep personal information for as long as your account is active and as needed to provide the Services, then retain what we must for legal, tax, accounting, and dispute-resolution purposes, after which we delete or anonymize it.
7. Security
We use technical and organizational measures including encryption in transit, tokenized payment storage, and encryption of sensitive credentials at rest. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
8. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information, and to object to processing or withdraw consent. California residents (CCPA/CPRA) and residents of other regions (including India’s DPDP Act) have specific rights. To exercise any right, contact us at [[email protected]]. You may also complain to your local data-protection authority.
9. International transfers
We may process information in countries other than yours. Where required, we use appropriate safeguards (such as standard contractual clauses) for such transfers.
10. Children
The Services are not directed to children under [13/16], and we do not knowingly collect their personal information. If you believe a child has provided us information, contact us and we will delete it.
11. Cookies
We use strictly necessary cookies/local storage to run the Services (e.g. to keep you signed in) and limited analytics storage to improve them. You can control cookies through your browser settings.
12. Changes to this policy
We may update this policy from time to time. We will post the new version here and update the “Last updated” date; material changes may be notified in-app or by email.
13. Contact us
[COMPANY LEGAL NAME] [Registered address] Email: [[email protected]]